SDN Connection Flow Re-Simulation for Correct Packet Forwarding
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing SDN connection tables in cloud architectures are not efficiently updated when policies change during the lifetime of a connection, leading to incorrect transformations or forwarding of packets.
Innovation Solution
Re-simulating the full packet processing paths using acceleration hardware to update the connection table after policy changes, ensuring all connections are correctly forwarded according to the latest policies.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If connection table is not updated after policy changes, then processing speed is maintained, but packet forwarding correctness deteriorates
Solution Approach 1:
The system performs preliminary actions by maintaining a connection table that is proactively updated through re-simulation when policies change. The hardware accelerator is pre-configured to re-simulate packet processing paths and update connection table entries before incorrect forwarding occurs, ensuring reliability without significant time loss.
2Reliability
If connection table is updated after policy changes, then packet forwarding correctness is improved, but processing time increases
Solution Approach 1:
The patent replaces the mechanical/software-based connection table update process with a hardware accelerator that performs re-simulation in parallel. This substitution dramatically increases update speed while maintaining accuracy, as the hardware device can process multiple connection table entries simultaneously through pipelined re-simulation of packet processing paths.
Solution Approach 2:
The system implements dynamic updating of the connection table based on policy change events. The hardware accelerator dynamically re-simulates only the affected packet processing paths when policies change, rather than static full-table updates, optimizing the balance between accuracy and speed by adapting the update scope to actual policy changes.
3Manufacturing precision
If full packet processing path is re-simulated for each connection, then policy update accuracy is improved, but computational overhead increases
Solution Approach 1:
The patent segments the packet processing path into discrete stages that can be independently re-simulated. The hardware accelerator divides the connection table into manageable entries and processes them through segmented pipeline stages, allowing precise policy application while reducing overall computational overhead through parallel processing of segmented paths.
Data Source
AI summary
Data flows in a virtualized computing environment are efficiently updated by a hardware-based networking device configured to disaggregate processing of data packets of the data flows from hosts of the virtualized computing environment. A connection table is accessed that defines connection flows for data packets having a source from an endpoint in a virtual network of the virtualized computing environment or a destination to the endpoint in the virtual network of the virtualized computing environment. The hardware-based networking device re-simulates full packet processing paths for each of the flows in the connection table and updates the flows in the connection table to ensure that the flows in the connection table implement policies of the virtualized computing environment that were updated after corresponding flows in the connection table were added to the connection table.


